GHSA-fpvg-m786-h5vr · Severity: high · Ecosystem: composer — Dolibarr vulnerable to unauthenticated database access
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
Conclusion & alert: CVE-2023-33568 is rated High Exploit Risk (80.4/100): CVSS High severity, with high exploitation likelihood (EPSS 89.84%, 100th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-01-03 | 89.26% | 89.84% | +0.58% |
| 2 | 2025-11-29 | 89.50% | 89.26% | -0.24% |
| 3 | 2025-11-21 | — | 89.50% | — |
Full EPSS history (41 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-fpvg-m786-h5vr · Severity: high · Ecosystem: composer — Dolibarr vulnerable to unauthenticated database access
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2023-33568 medium priority: Ubuntu including 1 source packages (dolibarr), 13 status rows across 13 suites (bionic, focal, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 9, ignored 2, needs-triage 2. | https://ubuntu.com/security/CVE-2023-33568 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| dolibarr | dolibarr_erp\/crm | >= 16.0.0, < 16.0.5 | cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/Dolibarr/dolibarr/commit/bb7b69ef43673ed403436eac05e0bc31d5033ff7 | Patch |
| https://github.com/Dolibarr/dolibarr/commit/be82f51f68d738cce205f4ce5b469ef42ed82d9e | Patch |
| https://www.dolibarr.org/forum/t/dolibarr-16-0-security-breach/23471 | Mitigation Vendor Advisory |
| https://www.dolibarr.org/forum/t/dolibarr-16-0-security-breach/23471/1 | Mitigation Vendor Advisory |
| https://www.dsecbypass.com/en/dolibarr-pre-auth-contact-database-dump/ | Exploit Third Party Advisory |